From: Jozsef Kadlecsik Date: Mon, 16 Sep 2013 18:07:35 +0000 (+0200) Subject: netfilter: ipset: Validate the set family and not the set type family at swapping X-Git-Tag: v3.12-rc2~14^2~10^2~2 X-Git-Url: http://review.tizen.org/git/?a=commitdiff_plain;h=169faa2e19478b02027df04582ec7543dba1dd16;p=platform%2Fkernel%2Flinux-stable.git netfilter: ipset: Validate the set family and not the set type family at swapping This closes netfilter bugzilla #843, reported by Quentin Armitage. Signed-off-by: Jozsef Kadlecsik --- diff --git a/net/netfilter/ipset/ip_set_core.c b/net/netfilter/ipset/ip_set_core.c index c8c303c..f2e30fb 100644 --- a/net/netfilter/ipset/ip_set_core.c +++ b/net/netfilter/ipset/ip_set_core.c @@ -1052,7 +1052,7 @@ ip_set_swap(struct sock *ctnl, struct sk_buff *skb, * Not an artificial restriction anymore, as we must prevent * possible loops created by swapping in setlist type of sets. */ if (!(from->type->features == to->type->features && - from->type->family == to->type->family)) + from->family == to->family)) return -IPSET_ERR_TYPE_MISMATCH; strncpy(from_name, from->name, IPSET_MAXNAMELEN);